Hackers Focus Efforts on Firefox, Safari
Internet Explorer goes unscathed, but Office is hit with new, dangerous bugs.
Stuart J. Johnston
Many people are switching from Internet Explorer to alternative browsers such as Firefox and Safari. Though that might make them feel more secure, the shift has also opened new doors for bad guys.
Case in point: We have no IE bugs to report this month, but both Firefox and Safari have been hit hard.
So forget the idea that just because you've switched to a new browser, you're magically safer. You may be for a time, but to stay safe with any software, you need to keep current with fixes.
Firefox Holes
In a somewhat dubious recognition of Firefox's growing popularity, hackers have focused their attention on it, leading to a rash of newly discovered holes. The folks at Mozilla recently released two Firefox updates in less than six weeks, fixing a total of five critical security vulnerabilities. All five can be exploited by planting a poisoned JavaScript file in a Web site and waiting for you to stumble across it.
In an actual attack--neither the Safari nor the Firefox bugs have elicited one so far--a bad guy could take over your PC or steal your navigation history.
The latest versions of Firefox--2.0.0.13 on--will stop all five bugs. Mozilla's Thunderbird and SeaMonkey are also at risk (if you have JavaScript enabled), so download updated versions.
Safari in the Wild
Safari 3.1 patches 13 holes affecting Mac OS X, Windows XP, and Windows Vista.
Think you're safe because you don't have Safari? You may have it without realizing it. Apple now distributes its browser with iTunes updates. Forget to uncheck a box in one of these updates, and it's there.
The Safari holes could allow an attacker to trick you into thinking that a fake site is really your bank site, or to take over your PC via a poisoned page. Download Safari 3.1.
Office Bugged Again
Microsoft recently released four patches that fix a dozen dangerous holes in Office. I warned you about one of those holes--a zero-day attack on Excel--in April. Be sure to apply the patches, if your system doesn't install them automatically. Get the four new Office patches and more info. (You are not affected if Microsoft Office 2007 is the version you use.)
No sooner had Microsoft shipped those patches than the company acknowledged the existence of yet another bad Office bug that needs patching. And this one is urgent because some users have already been attacked.
Luckily, Windows Vista, Windows Vista SP1, and the beta version of Windows XP SP3 are not at risk because they ship with a newer version of the affected "Jet" database. But earlier versions of Windows are vulnerable, as are all supported versions of Office, including Office 2007.
Becoming a victim of the bug involves saving two files to your PC's hard drive--one a mail-merge file that uses the database engine. There was no patch at press time. For more information, read Microsoft's advisory.
Found a hardware or software bug? Send us an e-mail on it to bugs@pcworld.com.
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
CDW Virtualization Center
PCW Download Guide
Tags at a Glance
Related Security Articles
- Virtualization Complicates Disaster Recovery The increasing popularity of virtualization is prompting IT organizations to rethink their disaster recovery plans, study says.
- Is Patient Data Getting Loose on Thumb Drives? Doctors are carrying unencrypted patient data on portable storage devices, a London study warns.
- Biggest Security Challenges An AT&T security guru reviews attacks, hackers, and training the next generation of security experts.
- Accused Spyware Vendor Sues 7Search.com disputes antivirus vendor McAfee's classification of its wares as spyware.
- How Do I Gain Administrator Access Without a Password? Anthony Venable purchased a used PC from a business going out of business. They didn't give him the password to the one administrator account.
Best Prices on Antivirus Software
Anti-Virus 7.0 (Electronic Software Distribution)Price: $29.95
VirusScan Plus 2008 - 3-User (Full Product)Price: $7.25
AntiVirus 2008 (Full Product)Price: $14.25
NOD32 AntiVirus 3.0Price: $19.00
Internet Security 2008 - 3 Users (Full Product)Price: $19.95
Norton AntiVirus 2008 - 3 UserPrice: $21.99
- Web Demo: Discover the Benefits of VoIP Is your company looking for a world class VoIP communications solution that will meet all of your business requirements? If so, join us for our Live Online Demo where you will receive a "guided tour" to the AltiGen Solution.
- PC World Webcast: Going Green Wondering how to make your business greener? These tips will help your business save money, and save the environment.
- A Windows Vista FAQ Corporate customers are deploying Windows Vista now, and Dell Services wants to help you understand the features of the new OS and how to plan your Windows Vista deployment.





"Hackers Focus Efforts on Firefox, Safari" Comments